#CA
openssl req -newkey rsa:2048 -nodes -keyout "UAS Root CA.key" -x509 -days 9131 -out "UAS Root CA.crt" -subj "/C=CN/L=SZ/O=UAS/OU=Root CA/CN=UAS Root CA"
#服务器
openssl genrsa -aes256 -passout pass:ef3d7fc7ad47f0a84a55d27bf45b48c9 -out ubtob.com.key 2048
openssl req -new -key ubtob.com.key -passin pass:ef3d7fc7ad47f0a84a55d27bf45b48c9 -out ubtob.com.csr -subj "/C=CN/ST=GD/L=SZ/O=ubtob.com/OU=Tech Research/CN=ubtob.com"
#签名
openssl x509 -req -days 3653 -in ubtob.com.csr -CA "UAS Root CA.crt" -CAkey "UAS Root CA.key" -passin pass:ef3d7fc7ad47f0a84a55d27bf45b48c9 -CAcreateserial -out ubtob.com.crt
#转为 pfx
openssl pkcs12 -export -in ubtob.com.crt -inkey ubtob.com.key -passin pass:ef3d7fc7ad47f0a84a55d27bf45b48c9 -password pass:ef3d7fc7ad47f0a84a55d27bf45b48c9 -out ubtob.com.p12 -name ubtob.com
其中:
-passin 为私钥(文件)密码(nodes 为无加密)-password 指定 p12 文件的密码(导入导出)